HydrogenAudio

Hosted Forums => foobar2000 => 3rd Party Plugins - (fb2k) => Topic started by: UTSquishy on 2018-07-09 18:34:46

Title: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: UTSquishy on 2018-07-09 18:34:46
On my home computer, my Anti-virus has been deleting foo_input_dts.dll, even when I tell it to restore the file and leave it alone, it will eventually ding it again. My home system tags it as a reputation thing, essentially claiming that there are so few users using that file, it must be a virus.

I've had this problem on my home system for a while, and I can get around it, but now my work computer (where I have no control over the anti-virus software) has decided it's malware and I can't even reinstall it. The software at work flags it as Gen:Variant.Razy.361336 - whatever that means.

Any insight would be helpful.
Title: Re: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: kode54 on 2018-07-09 23:13:09
False positive. I don't have a code signing certificate, so software has to build a reputation to bow to the Antivirus Overlords.

Here's the VirusTotal report, if you don't believe me:

https://www.virustotal.com/#/file/cf223a82c2c3dc7ed3cf338c01a0713f0c2f54bb58fd0fca823b497aabc93a47/detection
Title: Re: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: Porcus on 2018-07-10 10:08:35
@kode54: You only tested the .fb2k-component file. The .dll does unfortunately get some false positives, even among major suppliers.
https://www.virustotal.com/#/file/6d56184432db1a942d2b3399e00120274601ce0d297dc8f1832f63fba70c66b2/detection
Title: Re: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: kode54 on 2018-07-10 11:04:46
Apparently, I shouldn't be enabling debugging info in my releases (https://stackoverflow.com/questions/38573708/vs2015-executable-become-virus-with-potential-solution-but-dont-know-why), even though it's the only way to trace crashes from user crash logs, other than rebuilding a local copy with debugging info, then manually adding code offsets to the load address and tracing in a debugger.
Title: Re: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: kode54 on 2018-07-10 11:17:42
I'm deleting the component from everywhere it's published. Clearly, Peter needs to add his own DTS support to the application, using FFMPEG, and clearly, it will be better than anything I can offer.
Title: Re: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: Porcus on 2018-07-10 11:30:01
Why delete? Does it do any harm except an odd question now and then?
Title: Re: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: kode54 on 2018-07-10 11:32:40
It is a false positive that I have no idea how to solve, because I'm not a member of the antivirus cartel.
Title: Re: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: Porcus on 2018-07-10 12:24:56
Still: "Why delete?"
Title: Re: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: Case on 2018-07-10 13:24:01
You solve false positive issues by reporting them to the anti-virus company that makes the mistake. In this case most of the hits come from Bitdefender engine.
Title: Re: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: GeSomeone on 2018-07-13 09:47:55
I for one will definitely keep it around unless, like you say, really some better solution becomes available.
Title: Re: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: kode54 on 2018-07-14 03:42:43
I don't even know how to report false positives to Bitdefender. I'll get right on that.

E: Well, I'll get on it when I have my dev machine up and running again.
Title: Re: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: Zarggg on 2018-07-14 22:43:02
Why should you have to remove your component just because anti-virus software doesn't know what it's doing?
Title: Re: foo_input_dts.dll constantly being deleted by Antivirus software
Post by: kode54 on 2018-07-15 07:19:49
I was just being overly dramatic, is all. It's back up, with the same description. And apparently, someone has already submitted it to Bitdefender as a false positive, as it's only popping up in some obscure anti-virus software that don't really provide a mechanism for reporting false positives.